9.8

CVE-2018-14719

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

Data is provided by the National Vulnerability Database (NVD)
FasterxmlJackson-databind Version >= 2.0.0 < 2.6.7.3
FasterxmlJackson-databind Version >= 2.7.0 < 2.7.9.5
FasterxmlJackson-databind Version >= 2.8.0 < 2.8.11.3
FasterxmlJackson-databind Version >= 2.9.0 < 2.9.7
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
OracleBanking Platform Version2.5.0
OracleBanking Platform Version2.6.0
OracleBanking Platform Version2.6.1
OracleBanking Platform Version2.6.2
OracleClusterware Version12.1.0.2.0
OracleDatabase Server Version11.2.0.4
OracleDatabase Server Version12.1.0.2
OracleDatabase Server Version12.2.0.1
OracleDatabase Server Version18c
OracleDatabase Server Version19c
OracleGlobal Lifecycle Management Opatch Version < 11.2.0.3.23
OracleGlobal Lifecycle Management Opatch Version >= 12.2.0.1.0 < 12.2.0.1.19
OracleGlobal Lifecycle Management Opatch Version >= 13.9.4.0.0 < 13.9.4.2.1
OracleJdeveloper Version12.1.3.0.0
OracleJdeveloper Version12.2.1.3.0
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OracleWebcenter Portal Version12.2.1.3.0
RedhatOpenshift Container Platform Version >= 3.11 < 3.11.153
RedhatOpenshift Container Platform Version >= 4.6 < 4.6.26
RedhatOpenshift Container Platform Version >= 4.1 < 4.1.18
   RedhatEnterprise Linux Version7.0
NetappSnapcenter Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.65% 0.852
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7
Patch
Third Party Advisory
Release Notes
https://seclists.org/bugtraq/2019/May/68
Third Party Advisory
Mailing List
Issue Tracking